Dispute Over Public Disclosure of Ledger Ethereum App Vulnerability

iconCoinrise
Share
AI summary iconSummary
Dispute over public disclosure of a Ledger Ethereum app vulnerability has emerged, with Coinfomania crediting Ledger’s Donjon team and CryptoBriefing/The Cryptonomist EN pointing to external firm TestMachine. The flaw—a race condition bug—was patched on August 12, 2026, in version 1.22.2. Ledger’s CTO Charles Guillemet confirmed the fix and noted the issue was found using AI tools. No funds were lost. Amid rising scrutiny under CFT regulations, the incident raises questions about risk-on assets and security in the crypto space.

Coinfomania says Ledger's own Donjon team disclosed the Ethereum app vulnerability, while CryptoBriefing and The Cryptonomist EN say the public disclosure came from an external security researcher/firm, TestMachine.

Coinfomania says Ledger's own Donjon team disclosed the Ethereum app vulnerability, while CryptoBriefing and The Cryptonomist EN say the public disclosure came from an external security researcher/firm, TestMachine.

What all sources agree on

  • A race condition bug in Ledger's Ethereum app could have let a malicious dApp swap a legitimate transaction for a harmful one during signing.
  • The vulnerability was patched on August 12, 2026, shipping in Ethereum app version 1.22.2.
  • Ledger's internal security team, Donjon, discovered the flaw before any external party flagged it, using AI-assisted tools.
  • No confirmed reports of funds lost to the vulnerability had surfaced as of publication.
  • Ledger CTO Charles Guillemet commented publicly on the fix and the disclosure.

Where the reports disagree

1Who publicly disclosed the vulnerability

The issue was disclosed by Ledger Donjon, emphasizing proactive security measures.

Coinfomania2026-08-24 04:39

That changed between August 21 and 23, when a security researcher operating under the name TestMachine publicly disclosed the bug.

CryptoBriefing2026-08-24 04:07

Security firm TestMachine disclosed the bug publicly between August 21 and 23, 2026, using an AI agent called Azimuth.

The Cryptonomist EN2026-08-24 07:21

What would settle it: Ledger's own security advisory or TestMachine's original disclosure post identifying who published the finding and when.

What to make of it

Treat the underlying technical facts—the race condition bug, the August 12 patch in v1.22.2, and Donjon's internal discovery—as settled across all reports. The identity of who made the vulnerability public is contested and should not be repeated as fact until Ledger or TestMachine's own disclosure record is checked.

Treat the underlying technical facts—the race condition bug, the August 12 patch in v1.22.2, and Donjon's internal discovery—as settled across all reports. The identity of who made the vulnerability public is contested and should not be repeated as fact until Ledger or TestMachine's own disclosure record is checked.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.